Live data from Hacker News

US court system suffered 'incredibly significant attack' – sealed files at risk

theregister.com

11–20 of 28 posts

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#11

> sophisticated cyber security breach Like an unpatched Windows XP machine?

I mean, it’s possible, but I see no reason to assume that.

The article mentions files related to national security, so this isn’t your local school board. I’d expect they have at least decent security protocols in place.

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#13
post #8

But why are sealed files on the network?

I imagine so people that should have access (like prosecutors) can get to them without visiting the court house (and potentially requesting copies of the original)

I would have expected that a strong, physical audit trail would be a highly desirable thing.

That said, I have no idea what the transaction volume is like here. My experience of TV crime investigation tells me these are rare occurrences, under warrant.

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#14
post #9

But why are sealed files on the network?

The "seal" is a Legal construct not a engineering/technical one.

And before it was a digital version, a sealed file would be removed from the general filing system, kept under lock and key.

They seem to have forgotten basic security principles.

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#15

> sophisticated cyber security breach Like an unpatched Windows XP machine?

I mean, it’s possible, but I see no reason to assume that. The article mentions files related to national security, so this isn’t your local school board. I’d expect they have at least decent security protocols in place.

> I’d expect they have at least decent security protocols in place.

Don't expect too much from the government :)

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#17

But why are sealed files on the network?

Right? Every time I use PACER to look stuff up and I notice sealed-files in the docket, I think to myself, "PACER strikes me as very clunkily coded, and web programming is almost impossible to secure fully; apparently all that secures these files is simply the web app, they are foolish enough to commingle it all and count on access control denying the default of public access instead of storing them separately; I realize this is far more convenient than being offline or in separate systems entirely, but how has this not been hacked yet and all the sealed files exfiltrated?" Guess this answers that.

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#18

But why are sealed files on the network?

The same reason, in a health care context, that confidential patient data is: so that it an actually be worked with.

*so that it can cheaply be worked with

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#19

Earlier quoted context omitted.

There’s pretty immediate value in sealed records for blackmail purposes, though, so it could have just been non-state actors.

Nah, I think it's a state actor. Very obvious strategic move in line with a lot of other forms of attack underway. Of course they managed such an attack: it's really critical support of other stuff going on, a necessary component. In retrospect we'll chalk this time up not as a messy time of great chaos, but as an unprecedented form of world war that's killed more people than all previous wars combined, and done more…

Who is being killed?

Re: US court system suffered 'incredibly significant attack' – sealed files at risk

#20

But why are sealed files on the network?

The same reason, in a health care context, that confidential patient data is: so that it an actually be worked with.

So that it can be conveniently shared. I know "it's not supposed to be shared". Right? But that's policy, if a judge says "make it so" they'd have to. Right?
Post reply on HN